Fix Mattermost Calls, add Authelia to Asterisk web admin
Mattermost Calls: - Add 8443/udp to compose ports for the Calls plugin RTC server (WebRTC direct path; coturn relay is only the fallback, not the sole path) - Add 8443/udp to UFW rules and router port-forward table - Warn that WebRTC requires HTTPS — calls silently fail over HTTP - Prompt for Caddy domain and update MATTERMOST_SITE_URL in .env to match the HTTPS URL before Caddy is wired (previously SITEURL was written before the domain was known, leaving it as http://localhost:8065) - Update README with RTC server address field and corrected port table Asterisk web admin: - No built-in auth: add Authelia SSO check matching CLAUDE.md pattern - Set WEB_ADMIN_AUTH_DISABLED=true in .env when Authelia handles auth (prevents double-login prompts) https://claude.ai/code/session_014CCYqVwW6d6f5dw1qRokYt
This commit is contained in:
+14
-2
@@ -396,8 +396,20 @@ ENV
|
|||||||
|
|
||||||
chown -R "$ACTUAL_USER:$ACTUAL_USER" "$EA_DIR"
|
chown -R "$ACTUAL_USER:$ACTUAL_USER" "$EA_DIR"
|
||||||
|
|
||||||
# ── Caddy for web admin ───────────────────────────────────────────────────
|
# ── Caddy for web admin (with optional Authelia SSO) ──────────────────────
|
||||||
configure_caddy_for_service "Asterisk Web Admin" "localhost:8080" "asterisk"
|
# The web admin has no built-in auth; let Authelia gate it if available.
|
||||||
|
local EA_EXTRA_BLOCK=""
|
||||||
|
if [ -d "$DOCKER_DIR/authelia" ]; then
|
||||||
|
local _use_auth=""
|
||||||
|
prompt_yn "Protect Asterisk web admin with Authelia SSO? (y/n):" "y" _use_auth
|
||||||
|
if [[ "$_use_auth" =~ ^[Yy]$ ]]; then
|
||||||
|
EA_EXTRA_BLOCK=" import authelia"
|
||||||
|
# Tell Asterisk's web admin to skip its own auth — Authelia handles it
|
||||||
|
sed -i "s/^WEB_ADMIN_AUTH_DISABLED=.*/WEB_ADMIN_AUTH_DISABLED=true/" "$EA_DIR/.env"
|
||||||
|
log_info "WEB_ADMIN_AUTH_DISABLED=true set (Authelia will handle authentication)"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
configure_caddy_for_service "Asterisk Web Admin" "localhost:8080" "asterisk" "$EA_EXTRA_BLOCK"
|
||||||
|
|
||||||
# ── README ────────────────────────────────────────────────────────────────
|
# ── README ────────────────────────────────────────────────────────────────
|
||||||
write_readme "$EA_DIR" << MD
|
write_readme "$EA_DIR" << MD
|
||||||
|
|||||||
+68
-16
@@ -232,6 +232,7 @@ services:
|
|||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
ports:
|
ports:
|
||||||
- "8065:8065"
|
- "8065:8065"
|
||||||
|
- "8443:8443/udp" # Calls plugin RTC server (WebRTC direct path)
|
||||||
volumes:
|
volumes:
|
||||||
- ./data:/mattermost/data
|
- ./data:/mattermost/data
|
||||||
- ./logs:/mattermost/logs
|
- ./logs:/mattermost/logs
|
||||||
@@ -312,16 +313,17 @@ ENV
|
|||||||
echo ""
|
echo ""
|
||||||
log_info "Firewall — Mattermost coturn uses port 3479 (avoiding conflict with Easy Asterisk on 3478)."
|
log_info "Firewall — Mattermost coturn uses port 3479 (avoiding conflict with Easy Asterisk on 3478)."
|
||||||
if command -v ufw >/dev/null 2>&1 && ufw status 2>/dev/null | grep -q "Status: active"; then
|
if command -v ufw >/dev/null 2>&1 && ufw status 2>/dev/null | grep -q "Status: active"; then
|
||||||
log_info "Opening UFW ports for Mattermost coturn..."
|
log_info "Opening UFW ports for Mattermost..."
|
||||||
ufw allow 3479/udp comment "Mattermost coturn STUN/TURN"
|
ufw allow 8443/udp comment "Mattermost Calls RTC server" >/dev/null
|
||||||
ufw allow 3479/tcp comment "Mattermost coturn STUN/TURN TCP"
|
ufw allow 3479/udp comment "Mattermost coturn STUN/TURN" >/dev/null
|
||||||
ufw allow 49153:49352/udp comment "Mattermost coturn relay"
|
ufw allow 3479/tcp comment "Mattermost coturn STUN/TURN" >/dev/null
|
||||||
|
ufw allow 49153:49352/udp comment "Mattermost coturn relay" >/dev/null
|
||||||
log_success "UFW rules added"
|
log_success "UFW rules added"
|
||||||
else
|
else
|
||||||
log_info "UFW not active — add these rules manually if needed:"
|
log_info "UFW not active — add these rules manually if needed:"
|
||||||
echo " ufw allow 3479/udp comment \"Mattermost coturn STUN/TURN\""
|
echo " ufw allow 8443/udp # Mattermost Calls RTC"
|
||||||
echo " ufw allow 3479/tcp comment \"Mattermost coturn STUN/TURN TCP\""
|
echo " ufw allow 3479/udp && ufw allow 3479/tcp # coturn STUN/TURN"
|
||||||
echo " ufw allow 49153:49352/udp comment \"Mattermost coturn relay\""
|
echo " ufw allow 49153:49352/udp # coturn relay"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# ── Router port-forward instructions ──────────────────────────────────────
|
# ── Router port-forward instructions ──────────────────────────────────────
|
||||||
@@ -331,15 +333,62 @@ ENV
|
|||||||
echo " ├──────────────────┬──────────┬──────────────────────────────────┤"
|
echo " ├──────────────────┬──────────┬──────────────────────────────────┤"
|
||||||
echo " │ Port(s) │ Protocol │ Service │"
|
echo " │ Port(s) │ Protocol │ Service │"
|
||||||
echo " ├──────────────────┼──────────┼──────────────────────────────────┤"
|
echo " ├──────────────────┼──────────┼──────────────────────────────────┤"
|
||||||
|
echo " │ 8443 │ UDP │ Calls plugin RTC (direct WebRTC) │"
|
||||||
echo " │ 3479 │ UDP+TCP │ coturn STUN/TURN │"
|
echo " │ 3479 │ UDP+TCP │ coturn STUN/TURN │"
|
||||||
echo " │ 49153–49352 │ UDP │ coturn relay range │"
|
echo " │ 49153–49352 │ UDP │ coturn relay range │"
|
||||||
echo " └──────────────────┴──────────┴──────────────────────────────────┘"
|
echo " └──────────────────┴──────────┴──────────────────────────────────┘"
|
||||||
echo ""
|
echo ""
|
||||||
|
echo " ⚠ WebRTC (Calls) requires HTTPS. Calls will not work if Mattermost"
|
||||||
|
echo " is accessed over plain HTTP. Configure Caddy with a domain below."
|
||||||
|
echo ""
|
||||||
|
|
||||||
ensure_docker_dir_ownership "$DIR"
|
ensure_docker_dir_ownership "$DIR"
|
||||||
|
|
||||||
# ── Caddy reverse proxy ───────────────────────────────────────────────────
|
# ── Caddy reverse proxy ───────────────────────────────────────────────────
|
||||||
configure_caddy_for_service "Mattermost" "mattermost:8065" "chat"
|
# Mattermost's SITEURL must match the public URL for WebRTC (Calls) to work.
|
||||||
|
# If the user configures a Caddy domain here, update SITEURL in .env to match.
|
||||||
|
if [ -d "$DOCKER_DIR/caddy" ]; then
|
||||||
|
local _mm_domain=""
|
||||||
|
prompt_text "Caddy domain for Mattermost (e.g. chat.${SITE_DOMAIN:-example.com}) [skip]:" "" _mm_domain
|
||||||
|
if [[ -n "$_mm_domain" ]]; then
|
||||||
|
# Update SITEURL before wiring Caddy so the running container gets the right value
|
||||||
|
sed -i "s|^MATTERMOST_SITE_URL=.*|MATTERMOST_SITE_URL=https://$_mm_domain|" "$DIR/.env"
|
||||||
|
log_info "SITEURL updated → https://$_mm_domain (WebRTC requires HTTPS)"
|
||||||
|
# Write Caddyfile block directly (configure_caddy_for_service would prompt again)
|
||||||
|
local _caddyfile="$DOCKER_DIR/caddy/Caddyfile"
|
||||||
|
local _bk="$DOCKER_DIR/caddy/Caddyfile.backup.$(date +%Y%m%d-%H%M%S)"
|
||||||
|
[[ -f "$_caddyfile" ]] && cp "$_caddyfile" "$_bk" && log_info "Backed up Caddyfile"
|
||||||
|
if grep -q "^${_mm_domain}" "$_caddyfile" 2>/dev/null; then
|
||||||
|
log_warning "$_mm_domain already in Caddyfile — skipping block write"
|
||||||
|
else
|
||||||
|
cat >> "$_caddyfile" << MMCADDY
|
||||||
|
|
||||||
|
# Mattermost
|
||||||
|
$_mm_domain {
|
||||||
|
reverse_proxy mattermost:8065
|
||||||
|
|
||||||
|
header {
|
||||||
|
Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
|
||||||
|
X-Content-Type-Options "nosniff"
|
||||||
|
X-Frame-Options "SAMEORIGIN"
|
||||||
|
Referrer-Policy "strict-origin-when-cross-origin"
|
||||||
|
}
|
||||||
|
|
||||||
|
log {
|
||||||
|
output file /var/log/caddy/${_mm_domain}.log
|
||||||
|
format json
|
||||||
|
}
|
||||||
|
}
|
||||||
|
MMCADDY
|
||||||
|
docker exec caddy caddy fmt --overwrite /etc/caddy/Caddyfile 2>/dev/null || true
|
||||||
|
if docker exec caddy caddy reload --config /etc/caddy/Caddyfile 2>/dev/null; then
|
||||||
|
log_success "Mattermost accessible at: https://$_mm_domain"
|
||||||
|
else
|
||||||
|
log_warning "Caddy reload failed — check: docker logs caddy"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
# ── README ────────────────────────────────────────────────────────────────
|
# ── README ────────────────────────────────────────────────────────────────
|
||||||
write_readme "$DIR" << MD
|
write_readme "$DIR" << MD
|
||||||
@@ -358,24 +407,27 @@ The first user to sign up becomes the System Admin.
|
|||||||
|
|
||||||
## Calls plugin (voice/video)
|
## Calls plugin (voice/video)
|
||||||
The Mattermost Calls plugin provides voice/video channels.
|
The Mattermost Calls plugin provides voice/video channels.
|
||||||
|
**WebRTC requires HTTPS** — calls will not work over plain HTTP.
|
||||||
|
|
||||||
### Enable the plugin
|
### Enable the plugin
|
||||||
1. Go to **System Console → Plugins → Plugin Management**
|
1. Go to **System Console → Plugins → Plugin Management**
|
||||||
2. Enable the **Calls** plugin (pre-installed in Team Edition)
|
2. Enable the **Calls** plugin (pre-installed in Team Edition)
|
||||||
|
|
||||||
### Configure TURN server
|
### Configure ICE / TURN server
|
||||||
1. Go to **System Console → Plugins → Calls**
|
1. Go to **System Console → Plugins → Calls**
|
||||||
2. Set **TURN server URL**: \`turn:<your-server-ip>:3479\`
|
2. Set **RTC Server Address**: your server's public IP or domain
|
||||||
3. Set **TURN credentials type**: Static credentials (auth secret)
|
3. Set **TURN server URL**: \`turn:<your-server-or-ip>:3479\`
|
||||||
4. Set **TURN static auth secret**: (see TURN_SECRET in \`$DIR/.env\`)
|
4. Set **TURN credentials type**: Static credentials (auth secret)
|
||||||
5. Save and test a call
|
5. Set **TURN static auth secret**: (see \`TURN_SECRET\` in \`$DIR/.env\`)
|
||||||
|
6. Save and test a call in a channel
|
||||||
|
|
||||||
Clients outside your LAN need the TURN server to relay media. The coturn
|
Direct WebRTC (port 8443/UDP) is tried first; coturn relay is the fallback
|
||||||
container listens on port 3479 (UDP+TCP) with relay range 49153–49352/UDP.
|
for clients behind strict NAT (cellular, hotel WiFi, Proton VPN, etc.).
|
||||||
|
|
||||||
## Router port-forwards (for external calls)
|
## Router port-forwards (for external calls)
|
||||||
| Port(s) | Protocol | Service |
|
| Port(s) | Protocol | Service |
|
||||||
|--------------|----------|--------------------|
|
|--------------|-----------|---------------------------------|
|
||||||
|
| 8443 | UDP | Calls plugin RTC (direct path) |
|
||||||
| 3479 | UDP+TCP | coturn STUN/TURN |
|
| 3479 | UDP+TCP | coturn STUN/TURN |
|
||||||
| 49153–49352 | UDP | coturn relay range |
|
| 49153–49352 | UDP | coturn relay range |
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user